Skip to content

Latest commit

 

History

History
36 lines (30 loc) · 3.04 KB

File metadata and controls

36 lines (30 loc) · 3.04 KB

Introduction

JISEC-C0764 was developed by National Institute of Advanced Industrial Science and Technology, evaluated by ECSEC Laboratory, an Evaluation Facility in Japan, and certified by JISEC, CC Certification Body in Japan.

The same company name as the evaluation facility is included as a contributor, which leads to concerns about impartiality. This protection profile has several questionable descriptions as shown below:

Section 5.1.2

FDP_IFC.1/Import

A non-volatile memory of TOE is assigned as a subject of FDP_IFC.1.1/Import. Here the subject is considered as an active entity from the defintion of subject (see 3.88 of Common Criteria:2022 Part 1). Therefore the description can be considered as a non-conformity.

Section 7.1

FCS_COP.1/SKC

Table 7-1

AES-XTS

A cryptographic key length option 192-bit is specified for AES-XTS. AES-XTS using 192-bit is undefined as per IEEE 1619 and NIST SP 800-38E. Therefore the description is considered as a non-conformity.

It is stated that italicized and underlined text means "assignment completed". Here FCS_RBG_EXT.1.2 is drafted using the style italicized and underlined text, but, the number of noise sources is unspecified. Therefore, the assignment is not completed, and this contradicts with the style italicized and underlined text.

FCS_COP.1/SigVer

Table 7-3

ECDSA

Three options are specified for a cryptographic key length, 256-bit, 384-bit, and 512-bit. Here, when using NIST P-521 curve, the cryptographic key length shall be 521-bit, as per FIPS 186-5. Therefore the description is considered as a non-conformity.

ISO/IEC 10118-3:2018 Clause 10 cannot be applied.
Here EdDSA shall use either SHA-512 or SHAKE256 as per FIPS 186-5, while ISO/IEC ISO/IEC 10118-3:2018 Clause 10 specifies the specification of SHA-256, which cannot be used with EdDSA. Therefore the description is considered as a non-conformity.